Executive brief
A vulnerability in Kibana, a popular data visualization and management platform, could allow certain authorized users to access sensitive data they are not supposed to see. By abusing specific debugging tools within the Fleet management plugin, a user with limited administrative permissions can bypass security restrictions to read internal database records. This could lead to the unauthorized exposure of sensitive organizational data stored within the Elasticsearch cluster.
Technical details
A vulnerability classified as Execution with Unnecessary Privileges (CWE-250) exists in Kibana's Fleet plugin. The issue resides in the debug route handlers (specifically /internal/fleet/debug/index and /internal/fleet/debug/saved_objects), which execute with elevated privileges. An authenticated attacker with Fleet sub-feature permissions (such as agents, policies, or settings management) can leverage these routes to bypass Elasticsearch Role-Based Access Control (RBAC) and read index data they are not authorized to access. The vulnerability is present in default configurations where Fleet is enabled. Elastic has released patches in versions 8.19.14, 9.2.8, and 9.3.3 to address this flaw.
Affected products
- Elastic Kibana 8.0.0 to 8.19.13, 9.0.0 to 9.2.7, 9.3.0 to 9.3.2
Timeline
- 2026-04-08: disclosed
- 2026-04-08: patched
- 2026-04-08: advisory